github.com/google/go-attestation
Libraries to abstract aspects of working with TPMs for the purposes of attestation
Activity
- Latest release
- 1mo ago
- Total releases
- 21
- Cadence
- ~2 months
- Last 12 months
- 5
Reach
- Stars
- 438
Details
- First release
- Sep 06, 2019
| Version | Released | |
|---|---|---|
v0.6.4
patch
1 CVE
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev |
v0.6.4
patch
Dependencies (5)
|
|
v0.6.3
patch
1 CVE
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev |
v0.6.3
patch
Dependencies (4)
|
|
v0.6.2
patch
1 CVE
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev |
v0.6.2
patch
Dependencies (4)
|
|
v0.6.1
patch
1 CVE
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev |
v0.6.1
patch
Dependencies (4)
|
|
v0.6.0
minor
1 CVE
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev |
v0.6.0
minor
Dependencies (4)
|
|
v0.5.1
patch
1 CVE
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev |
v0.5.1
patch
Dependencies (5)
|
|
v0.5.0
minor
1 CVE
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev |
v0.5.0
minor
Dependencies (5)
|
|
v0.4.3
patch
1 CVE
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev |
v0.4.3
patch
Dependencies (6)
|
|
v0.4.2
patch
1 CVE
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev |
v0.4.2
patch
Dependencies (6)
|
|
v0.4.0
minor
1 CVE
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev |
v0.4.0
minor
Dependencies (6)
|
|
v0.4.1
patch
1 CVE
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev |
v0.4.1
patch
Dependencies (6)
|
|
v0.3.2
patch
2 CVEs
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev
CVE-2022-0317
GO-2022-0294
GHSA-99cg-575x-774p
Jul 15, 2022
Improper input validation in github.com/google/go-attestation A local attacker can defeat remotely-attested measured boot. Improper input validation in AKPublic.Verify can cause it to succeed when provided with a maliciously-formed Quote over no/some PCRs. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker can couple this vulnerability with a maliciously-formed TCG log in Eventlog.Verify to spoof events in the TCG log, defeating remotely-attested measured-boot. Fixed in
0.4.0
Updated May 20, 2024 · Source: OSV.dev |
v0.3.2
patch
Dependencies (6)
|
|
v0.3.1
patch
2 CVEs
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev
CVE-2022-0317
GO-2022-0294
GHSA-99cg-575x-774p
Jul 15, 2022
Improper input validation in github.com/google/go-attestation A local attacker can defeat remotely-attested measured boot. Improper input validation in AKPublic.Verify can cause it to succeed when provided with a maliciously-formed Quote over no/some PCRs. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker can couple this vulnerability with a maliciously-formed TCG log in Eventlog.Verify to spoof events in the TCG log, defeating remotely-attested measured-boot. Fixed in
0.4.0
Updated May 20, 2024 · Source: OSV.dev |
v0.3.1
patch
Dependencies (6)
|
|
v0.3.0
minor
2 CVEs
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev
CVE-2022-0317
GO-2022-0294
GHSA-99cg-575x-774p
Jul 15, 2022
Improper input validation in github.com/google/go-attestation A local attacker can defeat remotely-attested measured boot. Improper input validation in AKPublic.Verify can cause it to succeed when provided with a maliciously-formed Quote over no/some PCRs. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker can couple this vulnerability with a maliciously-formed TCG log in Eventlog.Verify to spoof events in the TCG log, defeating remotely-attested measured-boot. Fixed in
0.4.0
Updated May 20, 2024 · Source: OSV.dev |
v0.3.0
minor
Dependencies (6)
|
|
v0.2.3
patch
2 CVEs
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev
CVE-2022-0317
GO-2022-0294
GHSA-99cg-575x-774p
Jul 15, 2022
Improper input validation in github.com/google/go-attestation A local attacker can defeat remotely-attested measured boot. Improper input validation in AKPublic.Verify can cause it to succeed when provided with a maliciously-formed Quote over no/some PCRs. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker can couple this vulnerability with a maliciously-formed TCG log in Eventlog.Verify to spoof events in the TCG log, defeating remotely-attested measured-boot. Fixed in
0.4.0
Updated May 20, 2024 · Source: OSV.dev |
v0.2.3
patch
Dependencies (6)
|
|
v0.2.2
patch
2 CVEs
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev
CVE-2022-0317
GO-2022-0294
GHSA-99cg-575x-774p
Jul 15, 2022
Improper input validation in github.com/google/go-attestation A local attacker can defeat remotely-attested measured boot. Improper input validation in AKPublic.Verify can cause it to succeed when provided with a maliciously-formed Quote over no/some PCRs. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker can couple this vulnerability with a maliciously-formed TCG log in Eventlog.Verify to spoof events in the TCG log, defeating remotely-attested measured-boot. Fixed in
0.4.0
Updated May 20, 2024 · Source: OSV.dev |
v0.2.2
patch
Dependencies (6)
|
|
v0.2.1
patch
2 CVEs
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev
CVE-2022-0317
GO-2022-0294
GHSA-99cg-575x-774p
Jul 15, 2022
Improper input validation in github.com/google/go-attestation A local attacker can defeat remotely-attested measured boot. Improper input validation in AKPublic.Verify can cause it to succeed when provided with a maliciously-formed Quote over no/some PCRs. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker can couple this vulnerability with a maliciously-formed TCG log in Eventlog.Verify to spoof events in the TCG log, defeating remotely-attested measured-boot. Fixed in
0.4.0
Updated May 20, 2024 · Source: OSV.dev |
v0.2.1
patch
Dependencies (6)
|
|
v0.2.0
minor
2 CVEs
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev
CVE-2022-0317
GO-2022-0294
GHSA-99cg-575x-774p
Jul 15, 2022
Improper input validation in github.com/google/go-attestation A local attacker can defeat remotely-attested measured boot. Improper input validation in AKPublic.Verify can cause it to succeed when provided with a maliciously-formed Quote over no/some PCRs. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker can couple this vulnerability with a maliciously-formed TCG log in Eventlog.Verify to spoof events in the TCG log, defeating remotely-attested measured-boot. Fixed in
0.4.0
Updated May 20, 2024 · Source: OSV.dev |
v0.2.0
minor
Dependencies (6)
|
|
v0.1.3
patch
2 CVEs
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev
CVE-2022-0317
GO-2022-0294
GHSA-99cg-575x-774p
Jul 15, 2022
Improper input validation in github.com/google/go-attestation A local attacker can defeat remotely-attested measured boot. Improper input validation in AKPublic.Verify can cause it to succeed when provided with a maliciously-formed Quote over no/some PCRs. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker can couple this vulnerability with a maliciously-formed TCG log in Eventlog.Verify to spoof events in the TCG log, defeating remotely-attested measured-boot. Fixed in
0.4.0
Updated May 20, 2024 · Source: OSV.dev |
v0.1.3
patch
Dependencies (6)
|
|
v0.1.2
patch
2 CVEs
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev
CVE-2022-0317
GO-2022-0294
GHSA-99cg-575x-774p
Jul 15, 2022
Improper input validation in github.com/google/go-attestation A local attacker can defeat remotely-attested measured boot. Improper input validation in AKPublic.Verify can cause it to succeed when provided with a maliciously-formed Quote over no/some PCRs. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker can couple this vulnerability with a maliciously-formed TCG log in Eventlog.Verify to spoof events in the TCG log, defeating remotely-attested measured-boot. Fixed in
0.4.0
Updated May 20, 2024 · Source: OSV.dev |
v0.1.2
patch
Dependencies (5)
|
|
v0.1.1
initial
2 CVEs
CVE-2026-12681
GO-2026-5298
GHSA-9r4w-jg96-92mv
Jun 25, 2026
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation References Updated Aug 30, 2026 · Source: OSV.dev
CVE-2022-0317
GO-2022-0294
GHSA-99cg-575x-774p
Jul 15, 2022
Improper input validation in github.com/google/go-attestation A local attacker can defeat remotely-attested measured boot. Improper input validation in AKPublic.Verify can cause it to succeed when provided with a maliciously-formed Quote over no/some PCRs. Subsequent use of the same set of PCR values in Eventlog.Verify lacks the authentication performed by quote verification, meaning a local attacker can couple this vulnerability with a maliciously-formed TCG log in Eventlog.Verify to spoof events in the TCG log, defeating remotely-attested measured-boot. Fixed in
0.4.0
Updated May 20, 2024 · Source: OSV.dev |
v0.1.1
initial
Dependencies (6)
|